Skip to content

Changes

https://costdown.org
Compared to previous audit · 3 minutes ago View previous audit

Madrid, Spain New York, United Stated

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

1
New issues
4
Resolved
14
score changes
CategoryPreviousCurrentChange
CompositeA (91)A (91)
PerformanceA+ (97)A+ (97)
SecurityB (89)B (89)
AccessibilityA (90)A (90)
SEOA (95)A (95)
InfrastructureB (89)A (90) +1.000
ComplianceB (82)B (82)
ContentB (85)B (85)
SustainabilityA+ (98)A+ (98)
MetricPreviousCurrentChange
Performance 62008900 +2700
Accessibility 96009600
Best Practices 1000010000
SEO 91009100
PWA 00
Desktop Performance 99009800 -100
Desktop Accessibility 96009600
Desktop Best Practices 1000010000
Desktop SEO 92009200
FCP 2.66 s1.47 s -1.19 s
LCP 5.15 s3.50 s -1.65 s
TBT 445 ms130 ms -315 ms
CLS 0.0000.000
Desktop FCP 588 ms537 ms -50 ms
Desktop LCP 951 ms1.08 s +124 ms
Desktop TBT 4 ms0 ms -4 ms
Desktop CLS 0.0000.000
TTFB 537 ms337 ms -200 ms
DNS 10 ms1 ms -9 ms
TLS 11 ms24 ms +13 ms
Connect 2 ms17 ms +15 ms
Total 629 ms705 ms +76 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING 1 render-blocking <script src> tag(s) without async/defer performance
WARNING https://costdown.org/: 570ms CPU time performance
WARNING https://costdown.org/_next/static/chunks/1255-fc6c...: 255ms CPU time performance
WARNING Unattributable: 346ms CPU time performance
WARNING https://costdown.org/_next/static/chunks/webpack-a...: 305ms CPU time performance
CRITICAL Both www and non-www versions serve content infrastructure
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING X-Powered-By header reveals technology stack security
WARNING Permissions-Policy header not set -- features default to allow-on-same-origin security
WARNING No SPF record found security
WARNING All 1 images use legacy formats (JPEG/PNG/GIF) content
WARNING No Permissions-Policy header security
WARNING 1 images significantly larger than display size content
WARNING Registrar lock is NOT enabled infrastructure
WARNING No accessibility statement detected compliance
WARNING Permissions-Policy header is missing security
WARNING No DMARC record found security
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING Cross-Origin-Opener-Policy header is missing security
link
</_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro... </_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro...
content-security-policy
default-src 'self'; script-src 'self' 'nonce-fY8UdcavBgndB53IyUTo2A==' https:... default-src 'self'; script-src 'self' 'nonce-ZNm8y/uBD8sAbTKAbySrCA==' https:...

13 headers unchanged

Technology stack unchanged

11 technologies unchanged

Looking ahead

+6 pts
A (91) Could reach A+ (97)
Security +11Infrastructure +10Content +8Accessibility +4Compliance +4Performance +3

Estimate — actual results may vary (15 issues to fix)

Website improvement report — Costdown

August 27, 2026 → August 27, 2026

A A 91 → 91 0 pts

4

Resolved

1

New issues

14

Still remaining

Financial summary

Investment remaining

₫6,900,000 to complete the remaining items

Ongoing risk

₫3,325/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score91 (A)91 (A)0
Performance97 (A+)97 (A+)0
Security89 (B)89 (B)0
Accessibility90 (A)90 (A)0
SEO95 (A)95 (A)0
Infrastructure89 (B)90 (A)+1
Compliance82 (B)82 (B)0
Content85 (B)85 (B)0
Sustainability98 (A+)98 (A+)0

Resolved (4)

  • https://costdown.org/: 570ms CPU time (Performance)

    → Page loads faster for users

  • https://costdown.org/_next/static/chunks/1255-fc6c...: 255ms CPU time (Performance)

    → Page loads faster for users

  • Unattributable: 346ms CPU time (Performance)

    → Page loads faster for users

  • https://costdown.org/_next/static/chunks/webpack-a...: 305ms CPU time (Performance)

    → Page loads faster for users

Recommended next steps (15)

  • Sprint 1

    Both www and non-www versions serve content (Infrastructure)

  • Sprint 2

    1 render-blocking <script src> tag(s) without async/defer (Performance)

  • Sprint 2

    Cross-Origin-Embedder-Policy header is missing (Security)

  • Sprint 1

    X-Powered-By header reveals technology stack (Security)

  • Sprint 1

    Permissions-Policy header not set -- features default to allow-on-same-origin (Security)

  • Sprint 1

    No SPF record found (Security)

  • Sprint 2

    All 1 images use legacy formats (JPEG/PNG/GIF) (Content)

  • Sprint 1

    No Permissions-Policy header (Security)

  • Sprint 2

    1 images significantly larger than display size (Content)

  • Sprint 1

    Registrar lock is NOT enabled (Infrastructure)

  • Sprint 1

    No accessibility statement detected (Compliance)

  • Sprint 1

    Permissions-Policy header is missing (Security)

  • Sprint 2

    No DMARC record found (Security)

  • Sprint 1

    Skip navigation link is missing (WCAG 2.4.1) (Accessibility)

  • Sprint 1

    Cross-Origin-Opener-Policy header is missing (Security)

Send Feedback